Skip to main content
Administrator Guide
Last Updated: 2025-09-19
Steps: Set Up Constrained Prospect Security by Country

Steps: Set Up Constrained Prospect Security by Country

To set up constrained prospect security, you must have access to these security domains:
  • Set Up: Assignable Roles
  • Security Configuration
  • Set Up: Recruiting
  • Set Up: Security Administration
You can set up enhanced prospect security based on a prospect's country, allowing recruiters to view only the prospect data that's relevant to their assigned regions. This feature enables you to customize regions to align with your organization’s structure and helps your organization comply with General Data Protection Regulation (GDPR) requirements by restricting recruiter access by country.
To configure this functionality, you must first create recruiting regions that contain 1or more countries, and then assign roles to those regions. You can assign roles directly on the region or by using the role assignments on location hierarchies you add to the region.
Constrained prospect security by region applies only to prospects and candidates who have prospect records. This security won't apply if a job application exists without a corresponding prospect record.
These steps enable you to configure security for recruiting regions. If you plan to assign roles directly on the
Region of Recruiting
, follow steps 1-3. You can skip steps 1-3 if you only plan to use role assignments with location hierarchies added to the region for recruiting.
  1. Run the
    Maintain Assignable Roles
    task to create a new role.
    1. Add
      Region for Recruiting
      in the
      Enabled
      For
      column.
  2. Run the
    Create Security Group
    task.
    1. Select
      Role-Based Security Group
      (Constrained).
    2. Add a name.
    3. Select the role created in the previous step.
  3. Edit the domain security policies for security domains that apply from the attached list.
    If you need constrained access for specific domains, remove the unconstrained groups and add the constrained groups. (Example: The group you created in step 2).
    1. Prospects
    2. Prospect Sharing
    3. All Prospects
    4. Candidate: Global Search
    5. View Confidential Prospects
    6. Candidate Data: Personal Information and subdomains
    7. Manage: Prospect Consent
    8. Candidate Data: SMS Opt-In/Opt-Out
    9. Manage: Candidates
    10. Candidate Data: Other Information and subdomains
  4. Run the
    Create Region for Recruiting
    tasks.
    1. Enter the Name and Description.
    2. Select the
      Default Region
      checkbox to create a region that covers countries not specified in other regions.
    3. Select the
      Inactive
      checkbox to make the region inactive.
    4. Select 1 or more countries from the prompt.
    5. (Optional) Assign 1 or more roles.
    6. (Optional) Select 1 or more location hierarchies to use the role assignments on those location hierarchies.
    7. Ensure roles are assigned either directly or through location hierarchies.
  5. Repeat step 4 for any additional regions as per your requirements.
  6. (Optional) Run the Regions for Recruiting report to view all the regions that have been set up.
  7. Copy the
    Find Candidates
    report to and select the new data source filter
    Internal and External Candidates Secured by Prospect
    for the new report.
  8. Hide the existing Find Candidates report.
Workday applies the new security constraints to prospect data. After you create or edit regions, assign roles, or add or remove location hierarchies, you must allow 1 to 2 hours for the changes to propagate before the new security takes effect.
As a recruiter assigned to a certain region, login and search for candidates for that region. You can find candidates from your region using either search or the
Find Candidates
report that you created earlier. As expected, you won't be able to find or view candidates from other regions.